Cyber Resilience

CWE · MITRE source

CWE-345Insufficient Verification of Data Authenticity

Abstraction: Class · CVEs in our corpus: 719

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Last updated: 22 August 2026 20:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 26 mapping(s) from 7 framework(s): CAPEC 12 (partial) · ATT&CK 6 (partial) · STIG oracle linux 8 2 (mostly) · STIG rhel 7 2 (mostly) · STIG rhel 8 2 (mostly) · STIG oracle linux 9 1 (mostly) · STIG rhel 9 1 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A08:2025 Software or Data Integrity Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-17 Public Key Infrastructure Certificates
  • SC-20 Secure Name/Address Resolution Service (Authoritative Source)
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-33 Transmission Preparation Integrity
Detect
Catch it (CSF Detect / Respond)
  • RC.RP-05
Harden
Shrink the surface (DISA STIG)
  • 8 hardening rules · 5 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V3.5.5

NIST 800-53 r5 controls that address this weakness (9)AI-assisted

Showing the 7 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-17Public Key Infrastructure CertificatesSCUse of approved PKI certificates provides verifiable data authenticity and origin for communications and artifacts.
SC-20Secure Name/Address Resolution Service (Authoritative Source)SCMandates provision of authenticity and integrity artifacts that enable verification of name/address resolution data.
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)SCRequires explicit verification of data authenticity from authoritative sources, preventing acceptance of unauthenticated resolution responses.
SR-4ProvenanceSRProvenance documentation and monitoring directly enables verification of authenticity for components and data throughout their history.
SR-9Tamper Resistance and DetectionSRThe control implements verification mechanisms that detect tampering by ensuring data authenticity.
PT-8Computer Matching RequirementsPTDirectly requires independent verification of matching output before adverse decisions, mitigating insufficient authenticity checks on data from external sources.
SI-7Software, Firmware, and Information IntegritySIMandates verification of data authenticity for software, firmware, and information.
Show 2 more broadly-applicable controls
SC-33Transmission Preparation IntegritySCControl requires verification of data authenticity/integrity (e.g., checksums) after aggregation/packing, directly reducing exploitation of insufficient verification before transmission.
SC-45System Time SynchronizationSCTime synchronization supports reliable freshness verification when checking data authenticity across systems or components.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-26871 KEV 9.99.80.19632022-03-29
CVE-2016-4553 8.88.60.79972016-05-10
CVE-2023-38831 KEV 8.57.80.97812023-08-23
CVE-2016-4554 8.08.60.38892016-05-10
CVE-2018-19971 7.89.80.03032019-04-16
CVE-2019-11235 7.89.80.03572019-04-22
CVE-2022-31813 7.89.80.03352022-06-09
CVE-2025-59934 7.89.40.08042025-09-26
CVE-2013-2167 7.79.80.01972019-12-10
CVE-2020-28900 7.79.80.02362021-05-24
CVE-2021-37421 7.79.80.02492021-08-30
CVE-2017-3198 7.69.80.01602018-07-09
CVE-2022-25262 7.69.80.01442022-02-25
CVE-2022-31800 7.69.80.01532022-06-21
CVE-2024-454107.69.80.01502024-09-19
CVE-2015-3956 7.59.80.00952019-03-25
CVE-2019-18835 7.59.80.00862019-11-08
CVE-2022-0715 7.59.10.05852022-03-09
CVE-2020-14115 7.59.80.01122022-03-10
CVE-2022-31801 7.59.80.01082022-06-21
CVE-2022-30315 7.59.80.00912022-07-28
CVE-2023-4699 7.510.00.00752023-11-06
CVE-2025-59951 7.59.10.04652025-10-01
CVE-2019-6695 7.49.80.00772019-08-23
CVE-2019-2289 7.49.80.00612019-11-21